An IS auditor is comparing vulnerability assessment with penetration testing for a retail web estate. The chief information security officer has asked which technique should anchor the quarterly assurance cycle to give the broadest view of weaknesses on internet-facing hosts. Which response BEST reflects the appropriate selection?
- AQuarterly penetration testing anchors the cycle because exploitation evidence is the only credible indicator that a weakness is real.
- BConfiguration baseline review anchors the cycle because hardening drift is the dominant source of internet-facing weakness on web hosts.
- CAuthenticated vulnerability assessment anchors the cycle because it enumerates weaknesses broadly across hosts and informs targeted penetration testing. Correct
- DBug bounty intake anchors the cycle because crowdsourced research catches weaknesses that internal testing teams routinely overlook on production sites.
Why A is wrong: Exploitation evidence is valuable but slow and narrow; relying on it for breadth across an estate misses the catalogue of weaknesses a scanner would surface in the same window.
Why B is wrong: Baseline review is useful, but it addresses configuration drift rather than the full catalogue of missing patches, weak components and exposed services that a vulnerability assessment finds.
Why C is correct: Authenticated scanning gives breadth and patch-state visibility across the estate, which is the right tool for quarterly coverage; penetration testing is then targeted at the riskier findings.
Why D is wrong: Bounty programmes are a useful supplement, but they cannot guarantee coverage or cadence and they leave management without a structured quarterly inventory of weaknesses.